The Roger Blog - Notes of a software developer

In the code listed above, m_wndBrowser.GetControlUnknown() returns NULL and is assigned to the lpUnk variable, and later on a call to lpUnk->QueryInterface is done. There we have an access violation exception. Read more »

I'm currently porting FreeFixer for the Windows 7 platform. Luckily the different flavors of Windows does not differ that much from one release to another, so most of the unit tests worked without any changes to the existing code.
There's one piece of code that needed an update though, and it's the rootkit detection plugin, which in its current state detects hidden processes. This plugin uses the Windows Native API. The Native API is incompletely documented and used internally by the Windows NT operating systems (NT, XP, 2000, Vista, Win7, etc). FreeFixer calls the Native API by putting the system calls index in the eax register, and then using sysenter or int 2Eh depending on the platform. By using this procedure, FreeFixer can bypass some of the rootkit hooking techniques that hide running processes. Read more »

On Windows XP I had previously obtained the SeDebugPrivilege privilege (defined as SE_DEBUG_NAME) and then opened all processes with the OpenProcess system call and passing PROCESS_QUERY_INFORMATION | PROCESS_VM_READ as the requested access. However, on Windows Vista OpenProcess failed on Audiodg.exe, with the ACCESS_DENIED error code.
Windows Vista introduced a new type of process, the protected process. Protected processes are there to 'enhance support for digital rights management functionality in Windows Vista'. Read more »